Commit Graph

11360 Commits

Author SHA1 Message Date
Spencer McIntyre 06d1165a8b Remove dead code in the auxiliary/gather/enum_dns option 2020-10-30 10:45:08 -04:00
Grant Willcox 4479f4f0e1 Update library and module to fully support version 5.2. Also update the module to support guest discovery on newer versions on Zabbix 2020-10-29 19:27:12 -05:00
h00die 238889282a module cleanup 2020-10-29 17:11:19 -04:00
h00die c4e74c2ed0 wip chopslider 2020-10-29 15:33:37 -04:00
h00die f94acb94c9 cleanup 2020-10-29 10:46:14 -04:00
Spencer McIntyre 861879275e Land #14250, Fix how DNS enumeration displays AXFR results 2020-10-28 13:38:38 -04:00
Grant Willcox 85c3058e7d Delete the unused axfr function from auxiliary/gather/enum_dns 2020-10-28 09:34:13 -05:00
h00die 0abdaf9f67 WIP 2020-10-27 21:30:46 -04:00
h00die c11d07aed2 more cleanup 2020-10-27 17:53:30 -04:00
h00die 9c3b62f071 sqli help needed 2020-10-27 12:09:22 -04:00
Niboucha Redouane 17c7c4fdbe Fix issues 2020-10-27 00:55:06 +01:00
Grant Willcox bd57832494 First round of changes from review 2020-10-26 16:02:06 -05:00
Spencer McIntyre 291c883db8 Don't alter the os_name or os_flavor keys in report_host 2020-10-23 09:48:33 -04:00
Spencer McIntyre 3fdeb1933d Report the host details when scanning for MS17-010 2020-10-22 17:45:37 -04:00
Spencer McIntyre 2077f241c1 Support and use CheckCode details to share relevant information
Modules that can be used as check modules should be able to share
information with their exploit counterpart.
2020-10-21 16:29:31 -04:00
h00die f3a633b89e cve-2018-14847 2020-10-18 11:13:16 -04:00
h00die 252a5ace25 winbox_fileread 2020-10-17 13:12:25 -04:00
Karn Ganeshen 9a148bcaf4 new updates to module
added nil response and good response case, target hostname, and os details are now captured in hosts and services db, some cosmetics, fixed date format, and timeout handling.
2020-10-16 03:17:12 +05:30
Karn Ganeshen 262b51a659 Apache Zookeeper Information Disclosure
Adding new module for Zookeeper info disclosure
2020-10-15 16:54:38 +05:30
Faiz Azhar 193d15381e Cloudflare (NYSE:NET) is an independent company and unrelated to Amazon (NASDAQ: AMZN) 2020-10-10 00:13:43 +08:00
Grant Willcox 7cc9d663dc Land #14242, Remove modules whose deprecation date has past 2020-10-08 11:34:00 -05:00
Spencer McIntyre 3431d97c64 Remove modules whose deprecation date has past 2020-10-08 10:56:37 -04:00
Vladimir Ivanov d2ee5a838a Update sap_service_discovery.rb
Add port 40080 - SAP Internet Graphics Server [HTTP]
2020-10-08 13:51:44 +03:00
Grant Willcox a2675c13e8 Land #14213, Add disclosure date rubocop linting rule - enforce iso8601 disclosure dates 2020-10-07 12:09:59 -05:00
Ivanov Vladimir fa7b711d60 Change ltype in loot 2020-10-07 10:12:09 -05:00
Grant Willcox 12095f9174 Make minor updates to the error messages 2020-10-07 10:12:09 -05:00
Ivanov Vladimir df86b0c7c2 Update script to ensure action_file_read will correctly use fail_with, and to update the return types of send_first_request. 2020-10-07 10:11:12 -05:00
Grant Willcox 5ad2190c40 Apply updates to the module from the review process and a minor update to the documentation to note the renaming of the PATH option to URIPATH. Also update the check method so that it now works correctly and so that other functions return errors appropriately. 2020-10-07 10:08:57 -05:00
Ivanov Vladimir cc721fd64f Update several functions to apply review edits and also update the documentation accordingly. 2020-10-07 10:07:48 -05:00
Ivanov Vladimir 9ce3dc45f7 Delete default option: VERBOSE 2020-10-07 10:07:46 -05:00
Ivanov Vladimir 24d14f8816 Rename URN to PATH in several functions. Also change check function. 2020-10-07 10:04:55 -05:00
Grant Willcox 8a8dfafcc3 Rename the files and update some descriptions as there may be more XXE bugs in SAP in the future. Also update the documentation accordingly. 2020-10-07 10:04:03 -05:00
Grant Willcox fc462d2465 Clean up code to remove some extra options and to make the match() calls a bit cleaner, as well as make some of the explanations a bit neater. Also remove duplicate code from a few places 2020-10-07 10:04:02 -05:00
Grant Willcox a70cb25824 Remove all verbose options and tidy up one extra instance variable that was only used once 2020-10-07 10:04:02 -05:00
Vladimir Ivanov 7c682af98b Create sap_igs_xxe.rb and its associated documentation, and apply RuboCop fixes. 2020-10-07 10:03:09 -05:00
Alan Foster 30809787c4 Convert disclosure dates to iso8601 2020-10-02 21:00:37 +01:00
Alan Foster 26ff912291 Fix invalid disclosure date formats 2020-10-02 12:20:05 +01:00
Spencer McIntyre bf13ffc692 Update documentation based on feedback 2020-10-01 09:19:15 -04:00
Christophe De La Fuente 94796f5c91 Updates from review #2 2020-09-30 15:01:54 +02:00
Spencer McIntyre d53da9a83a Always show the plain password value of the machine account 2020-09-29 16:17:02 -04:00
Spencer McIntyre d91a9a0468 Consolidate the aes_cts_hmac_sha1_96_key functions 2020-09-29 16:05:06 -04:00
Christophe De La Fuente 67821e32c4 Password cracking integration 2020-09-29 20:36:39 +02:00
Christophe De La Fuente 9cb419ae8c Resync with master branch 2020-09-28 15:45:02 +02:00
Christophe De La Fuente 59fff3d7fe Land #14161, VyOS config processor 2020-09-28 13:02:19 +02:00
Grant Willcox 1710b98ba4 Land #14173, Unify the socks modules using a VERSION option 2020-09-22 17:09:34 -05:00
Spencer McIntyre a14780d024 Update the zerologon options for clarity 2020-09-22 14:57:57 -04:00
Spencer McIntyre a67379d1e1 Fix rubocop complaints 2020-09-22 10:28:58 -04:00
Spencer McIntyre 77f0d90bf0 Unify the socks modules using a VERSION option 2020-09-22 10:16:00 -04:00
Spencer McIntyre 3ae4eb3dce Convert the BinData error_status value to a Ruby integer 2020-09-21 11:38:33 -04:00
h00die 610d4d86d2 initial vyos implementation 2020-09-20 19:48:20 -04:00